> parcours
Apprendre l’analyse de malwares
Un parcours structuré, du fonctionnement d’un binaire jusqu’à l’analyse automatisée. Chaque leçon se termine par un lab sûr, sur des programmes que vous compilez vous-même.
Module 01 · 4 leçons · ~120 min
Fondations
Pourquoi analyser des malwares, comment le faire en sécurité, et ce qu'est vraiment un binaire — du code source au processus.
- 1.1What Is Malware Analysis?Why defenders reverse engineer malicious binaries, what questions analysis answers, and how triage, static and dynamic analysis fit together.20 min
- 1.2Building a Safe Analysis LabSet up isolated Windows and Linux analysis VMs with simulated networking, snapshots and safe sample-handling habits before touching any malware.35 min
- 1.3From Source Code to BinaryFollow a C program through preprocessing, compilation, assembly and linking, and learn what symbols, relocations and debug info leave behind.30 min
- 1.4How a Binary Is Loaded and RunWhat happens between double-clicking an executable and main(): process creation, memory mapping, the loader, imports, ASLR, CRT startup and TLS callbacks.35 min
Module 02 · 5 leçons · ~195 min
Formats binaires
Le format PE en profondeur — en-têtes, sections, imports, exports et ressources — et l'essentiel d'ELF pour les malwares Linux.
- 2.1PE Headers: DOS, NT and Optional HeaderWalk the headers at the start of every Windows executable, byte by byte, and learn which fields analysts trust, which they doubt and which malware abuses.40 min
- 2.2PE Sections and Memory LayoutHow the section table maps a PE file into memory, how to convert RVAs to file offsets, and which section anomalies betray packers and loaders.40 min
- 2.3Imports, Exports and the IATHow PE files declare the API functions they use and provide, how the loader fills the IAT, and how malware hides its imports from you.45 min
- 2.4Resources, Overlays and Other Hiding PlacesWhere PE files carry data outside their code: the resource tree, version info, overlays, Authenticode signatures, and the .NET and TLS directories.35 min
- 2.5ELF for Malware AnalystsThe ELF essentials for Linux malware: headers, sections versus segments, dynamic linking, and why stripped, static and header-less binaries still run.35 min
Module 03 · 6 leçons · ~250 min
Triage statique
Répondre aux premières questions sur un échantillon en quelques minutes, sans l'exécuter — et en tirer des détections.
- 3.1Identifying and Hashing FilesIdentify a file by its magic bytes rather than its name, then fingerprint it with cryptographic, import, fuzzy and Rich header hashes.40 min
- 3.2Strings and Obfuscated StringsExtract ASCII and UTF-16 strings, separate indicators from runtime noise, and recover stack, XOR and decoded strings with FLOSS and CyberChef.45 min
- 3.3Reading Capabilities from ImportsTurn a PE import table into a capability hypothesis: group APIs by behaviour, spot suspicious combinations, and use capa to confirm with code evidence.35 min
- 3.4Detecting Packers and EntropyRecognise packed and encrypted executables with entropy, section anomalies, import tables and signatures — and avoid the classic false positives.35 min
- 3.5Writing Your First YARA RulesTurn triage findings into YARA rules: strings, hex patterns, the pe and math modules, performance, and testing against goodware and variants.50 min
- 3.6Writing a Triage ReportTurn static triage into a report people can act on: verdict and confidence, ATT&CK-mapped capabilities, defanged IOCs, detections and next steps.45 min
Module 04 · 5 leçons · ~245 min
Désassemblage & analyse de code
Comment les désassembleurs retrouvent le code, lire la sortie du compilateur, et s'aider des flots de contrôle et de données.
- 4.1Linear vs Recursive DisassemblyHow disassemblers decide which bytes are code, why linear sweep and recursive descent fail in different ways, and how to build a tiny recursive disassembler.45 min
- 4.2Functions and Control-Flow GraphsSplit code into basic blocks, read the CFG shapes of ifs, loops and switches, find x64 Windows function boundaries, and build a CFG with Capstone.50 min
- 4.3Recognising Compiler IdiomsMap optimised x86-64 compiler output back to C: frames, magic-number division, branchless code, loops, jump tables, structs and vtables.50 min
- 4.4Decompilers and Their LimitsHow decompilers turn machine code into C-like pseudocode, where that output misleads you, and how to repair it with types, names and signatures.50 min
- 4.5Cross-References and Data FlowUse cross-references to pivot from strings and imports to the code that uses them, trace values backwards, and restore xrefs lost to indirect calls.50 min
Module 05 · 5 leçons · ~40 min
Windows pour analystes
Les notions Windows sur lesquelles s'appuient les malwares — API et API native, processus, threads, DLL, mutex, services, registre et frontière user/kernel.
- 5.1The Windows API for AnalystsBientôt
- 5.2Processes, Threads and DLLsWhat processes, threads and DLLs look like to an observer — PEB, TEB, tokens, handles, process trees and module lists — and how to read them as evidence.40 min
- 5.3The Registry, Services and Scheduled TasksBientôt
- 5.4Mutexes, Events and Inter-Process CommunicationBientôt
- 5.5User Mode, Kernel Mode and the Native APIBientôt
Module 06 · 5 leçons · ~220 min
Analyse dynamique
Exécuter les échantillons sous observation — surveillance comportementale, simulation réseau, débogage, traçage d'API et dump mémoire.
- 6.1Behavioural MonitoringRun a sample through a repeatable detonation routine with Process Monitor, Sysmon, registry diffs and Autoruns, then turn what you see into host IOCs.40 min
- 6.2Simulating and Capturing Network TrafficKeep a sample's traffic inside the lab with INetSim and FakeNet-NG, capture it, and read DNS, HTTP, beacon timing and TLS fingerprints as network IOCs.40 min
- 6.3Debugging Malware with x64dbgHow debuggers stop and step a process, how to drive x64dbg around a sample, and the analyst loop: break on an API, read its arguments, flip a branch.50 min
- 6.4Tracing API and System CallsRecord a sample's API and system calls instead of stepping through them, cut the noise, read the trace as behaviour, and know where tracing goes blind.45 min
- 6.5Dumping Memory and Extracting PayloadsCapture process and system memory, find the region that holds the real payload, and turn a memory-layout PE back into a file your tools can parse.45 min
Module 07 · 6 leçons
Comportements malveillants
Ce que font réellement les malwares et comment chaque comportement apparaît dans le code et la télémétrie — persistance, C2, vol d'identifiants, injection et furtivité.
- 7.1Loaders, Droppers and DownloadersBientôt
- 7.2Persistence MechanismsBientôt
- 7.3Command and ControlBientôt
- 7.4Credential Theft and KeyloggingBientôt
- 7.5Understanding Process InjectionBientôt
- 7.6Hooking and User-Mode RootkitsBientôt
Module 08 · 5 leçons · ~255 min
Encodage, crypto & signatures
Reconnaître encodages et cryptographie, extraire les configurations, et transformer ce que vous décodez en signatures réseau et hôte.
- 8.1Recognising XOR, Base64 and Custom EncodingsSpot XOR, rolling-key and custom Base64 encodings in data and in code, recover their keys with key-length tests and known plaintext, and decode them.45 min
- 8.2Identifying Cryptographic AlgorithmsTell encryption from encoding, identify AES, RC4, ChaCha20, TEA, hashes and CRC32 from constants, loops and imports, then locate the key and IV to report.50 min
- 8.3Scripting String DecryptionRecover hundreds of encrypted strings at once by finding the decrypt routine, recovering each call's arguments statically, and scripting the algorithm.55 min
- 8.4Extracting Malware ConfigurationsTurn a sample's embedded configuration into normalised JSON with a locate-decode-parse-output extractor, and share the results responsibly.55 min
- 8.5Writing Network SignaturesTurn a sample's network code and captured traffic into Suricata rules that target durable protocol structure, then test them against pcaps.50 min
Module 09 · 6 leçons · ~185 min
Évasion & unpacking
Déjouer les pièges qui font perdre du temps aux analystes — anti-désassemblage, anti-débogage, détection de sandbox et packing — par patching, hooking et unpacking.
- 9.1Anti-DisassemblyRecognising the tricks that make a disassembler lie — constant-condition jumps, overlapping instructions, rogue bytes — and repairing the listing.45 min
- 9.2Anti-DebuggingThe families of debugger detection — API calls, PEB and heap flags, timing and hardware checks — how to spot each in a sample and get past it.50 min
- 9.3Anti-VM and Sandbox EvasionBientôt
- 9.4Patching Binaries to Defeat ChecksUse patching as an analysis tool: flip a jump, NOP a check or force a return so a sample reveals what it hides, in memory or on the file.45 min
- 9.5How Packers WorkWhat a packer's unpacking stub does step by step — decompress, rebuild imports, relocate, jump to the OEP — and what it means for unpacking.45 min
- 9.6Manual Unpacking to the OEPBientôt
Module 10 · 4 leçons · ~180 min
Au-delà de l'EXE
Les malwares qui ne sont pas des exécutables natifs — shellcode, assemblies .NET, scripts et documents malveillants — et les outils adaptés.
- 10.1Shellcode AnalysisHow to recognise raw shellcode without headers, follow its get-PC and API-resolution idioms, and disassemble, emulate and extract IOCs from it safely.45 min
- 10.2Analysing .NET MalwareHow to recognise a .NET assembly, read its metadata and IL, pick the right decompiler, and get past obfuscators and in-memory stages.45 min
- 10.3PowerShell, JavaScript and VBScript MalwareDeobfuscate malicious PowerShell, JavaScript and VBScript without running them: neutralise eval sinks, decode layers, read script logs, extract IOCs.45 min
- 10.4Malicious Documents and ArchivesTriage malicious Office files, RTF, PDF, archives, disk images and LNK shortcuts without opening them, and pull out the next stage and its IOCs.45 min
Module 11 · 5 leçons · ~205 min
Analyse automatisée & avancée
Laisser les outils travailler — instrumentation, émulation, analyse de teinte, exécution symbolique et chaînes d'analyse.
- 11.1Dynamic Binary InstrumentationHow DBI engines like Pin, DynamoRIO, Frida and TinyInst inject analysis code into a running sample to log API calls, map coverage and catch unpacking.50 min
- 11.2Emulating Code with Unicorn and SpeakeasyWhy analysts emulate instead of run, CPU vs OS-level emulators, and how to call a sample's own decryption routine with stubbed APIs.55 min
- 11.3Dynamic Taint AnalysisHow taint tracking follows data from sources to sinks, the design choices that cause over- and under-tainting, and how analysts use it on malware.50 min
- 11.4Symbolic Execution with angrBientôt
- 11.5Building an Analysis PipelineTurn manual triage into a repeatable pipeline: deduplication, file-type routing, static enrichment, scoring, safe isolation and reproducible reports.50 min